Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,388 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 146 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2013-3502 | monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive information, by leveraging a JOSSO SSO cookie. | EXPLOIT ✓MEDIUM 6.5EPSS 53.7% | 8 May 2013 |
| CVE-2013-1347 | Microsoft Internet Explorer Remote Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 77.7% | 5 May 2013 |
| CVE-2013-0726 | Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 13.00.0001 allows remote attackers to execute arbitrary code via a crafted pathname in an ERS file. | EXPLOIT ✓HIGH 9.3EPSS 28.0% | 5 May 2013 |
| CVE-2013-3242 | 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unspecified vectors. | EXPLOIT ✓MEDIUM 5.5EPSS 4.85% | 3 May 2013 |
| CVE-2013-1959 | kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying… | EXPLOITLOW 3.7EPSS 1.24% | 3 May 2013 |
| CVE-2013-1884 | The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized… | EXPLOIT ✓MEDIUM 5.0EPSS 50.5% | 2 May 2013 |
| CVE-2013-1847 | The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist. | EXPLOIT ✓MEDIUM 5.0EPSS 51.4% | 2 May 2013 |
| CVE-2009-5029 | Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd. | EXPLOIT ✓MEDIUM 6.8EPSS 8.07% | 2 May 2013 |
| CVE-2009-5135 | The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | EXPLOIT ✓MEDIUM 5.0EPSS 9.92% | 2 May 2013 |
| CVE-2013-0699 | The Galil RIO-47100 Pocket PLC allows remote attackers to cause a denial of service via a session that includes "repeated requests." | EXPLOITHIGH 7.1EPSS 2.79% | 1 May 2013 |
| CVE-2013-0140 | SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication… | EXPLOITHIGH 7.9EPSS 2.54% | 1 May 2013 |
| CVE-2012-5946 | Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code via a long TabCaption string. | EXPLOIT ✓HIGH 9.3EPSS 33.8% | 30 April 2013 |
| CVE-2013-3301 | The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access… | EXPLOIT ✓HIGH 7.2EPSS 0.98% | 29 April 2013 |
| CVE-2013-1428 | Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet. | EXPLOIT ✓MEDIUM 6.5EPSS 60.7% | 26 April 2013 |
| CVE-2013-3241 | export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal array, which allows remote authenticated users to inject values via a crafted request. | EXPLOIT ✓MEDIUM 4.0EPSS 4.19% | 26 April 2013 |
| CVE-2013-3240 | Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files or possibly have unspecified other impact via a parameter that specifies a crafted export type. | EXPLOIT ✓MEDIUM 6.5EPSS 5.49% | 26 April 2013 |
| CVE-2013-3239 | phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this… | EXPLOIT ✓MEDIUM 4.6EPSS 8.75% | 26 April 2013 |
| CVE-2013-3238 | phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature. | EXPLOIT ×2 ✓MEDIUM 6.0EPSS 28.9% | 26 April 2013 |
| CVE-2013-3075 | Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code via a long string, as demonstrated by a long WzTitle… | EXPLOIT ✓HIGH 10.0EPSS 10.8% | 19 April 2013 |
| CVE-2013-1748 | Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) edit.php or (2) import.php. | EXPLOIT ✓HIGH 7.5EPSS 1.02% | 18 April 2013 |
| CVE-2013-2423 | Oracle JRE Unspecified Vulnerability | KEVEXPLOIT ✓LOW 3.7EPSS 85.2% | 17 April 2013 |
| CVE-2013-2419 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown… | EXPLOITMEDIUM 5.0EPSS 22.6% | 17 April 2013 |
| CVE-2013-2416 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment. | EXPLOITMEDIUM 4.3EPSS 8.77% | 17 April 2013 |
| CVE-2013-1559 | Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect availability via unknown vectors related to Content Server. | EXPLOIT ✓MEDIUM 4.0EPSS 58.8% | 17 April 2013 |
| CVE-2013-1509 | Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2, 11.1.1.6.0, and 11.1.1.6.1 allows remote authenticated users to affect integrity via unknown vectors related to WebCenter Sites. | EXPLOITMEDIUM 4.0EPSS 2.21% | 17 April 2013 |
| CVE-2013-2760 | Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file. | EXPLOIT ✓MEDIUM 6.8EPSS 3.55% | 16 April 2013 |
| CVE-2013-1937 | Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2)… | EXPLOIT ✓MEDIUM 6.1EPSS 7.87% | 16 April 2013 |
| CVE-2013-3050 | SQL injection vulnerability in ZAPms 1.41 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter to product. | EXPLOIT ✓HIGH 7.5EPSS 1.31% | 12 April 2013 |
| CVE-2013-0135 | Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3)… | EXPLOIT ×11 ✓HIGH 7.5EPSS 2.98% | 9 April 2013 |
| CVE-2013-0109 | The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, which allows local users to gain privileges or cause a denial of service (memory overwrite) via a… | EXPLOIT ✓HIGH 7.2EPSS 4.47% | 8 April 2013 |
| CVE-2013-0125 | Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File parameter. | EXPLOIT ✓MEDIUM 4.3EPSS 1.68% | 4 April 2013 |
| CVE-2013-0663 | Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote… | EXPLOITMEDIUM 6.8EPSS 5.96% | 4 April 2013 |
| CVE-2012-1038 | Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3… | EXPLOIT ✓MEDIUM 4.3EPSS 1.62% | 3 April 2013 |
| CVE-2012-6550 | Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipText returned from the flash object," a different vulnerability than CVE-2013-1808. | EXPLOIT ✓MEDIUM 4.3EPSS 4.54% | 2 April 2013 |
| CVE-2013-1080 | The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently… | EXPLOIT ✓HIGH 10.0EPSS 77.0% | 29 March 2013 |
| CVE-2012-6534 | Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data… | EXPLOITMEDIUM 4.3EPSS 4.49% | 29 March 2013 |
| CVE-2013-2690 | SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff action. | EXPLOITHIGH 7.5EPSS 2.51% | 28 March 2013 |
| CVE-2013-1861 | MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted… | EXPLOIT ✓MEDIUM 5.0EPSS 18.7% | 28 March 2013 |
| CVE-2012-5879 | An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or create arbitrary files via a full pathname argument to the Save method. | EXPLOITHIGH 8.2EPSS 5.20% | 28 March 2013 |
| CVE-2013-2501 | Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field. | EXPLOIT ✓MEDIUM 4.3EPSS 5.27% | 22 March 2013 |
| CVE-2013-1828 | The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size value before proceeding to a copy_from_user operation, which allows local users to gain privileges via a crafted application that… | EXPLOITMEDIUM 6.9EPSS 1.01% | 22 March 2013 |
| CVE-2013-0126 | Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allow remote attackers to hijack the authentication of administrators for requests that (1) add… | EXPLOITMEDIUM 6.8EPSS 2.94% | 21 March 2013 |
| CVE-2013-0332 | Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 10.2% | 20 March 2013 |
| CVE-2013-0232 | includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command… | EXPLOIT ✓HIGH 7.5EPSS 47.9% | 20 March 2013 |
| CVE-2013-2492 | Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during… | EXPLOIT ✓MEDIUM 6.8EPSS 42.2% | 15 March 2013 |
| CVE-2013-2560 | Directory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read arbitrary files via a .. | EXPLOIT ✓HIGH 7.8EPSS 9.28% | 15 March 2013 |
| CVE-2013-1468 | Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors. | EXPLOIT ✓HIGH 7.6EPSS 5.73% | 14 March 2013 |
| CVE-2013-1814 | The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password… | EXPLOITMEDIUM 4.0EPSS 73.8% | 14 March 2013 |
| CVE-2013-1469 | Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. | EXPLOIT ×2 ✓MEDIUM 4.0EPSS 56.0% | 13 March 2013 |
| CVE-2013-0090 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability." | EXPLOIT ✓HIGH 8.8EPSS 38.2% | 13 March 2013 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.